• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI Go App Security Problems: DJI Responds to Reports of Potential Flight System Software Vulnerabilities

July 29, 2020 by Miriam McNabb 11 Comments

DJI Go App security problemsAre reports of DJI Go App security problems overblown, or cause for concern?

By DRONELIFE staff writer, Jim Magill

Two related studies, released last week by a pair of cybersecurity companies, claim to reveal potential flaws in a DJI flight operation software system, which researchers say could be exploited “to target specific users with malicious updates or applications that could be used to exploit the user’s phone.”

In its response, DJI said the reports “found typical software concerns, with no evidence they have ever been exploited.” The reports are just the latest example of security issues being raised about the Chinese-based drone manufacturing and software company, which for some time has been under scrutiny by lawmakers and members of the current administration in Washington.

DJI Go App Security Problems

In a blog post Cybersecurity firm GRIMM released it findings on potential privacy concerns of DJI drones within the Android DJI GO 4 application.  Researchers at GRIMM partnered with IT security company Synacktiv, which performed an in-depth dynamic and static analysis of the application.

GRIMM found the DJI GO 4 application “contains a self-update feature that bypasses the Google Play store,” and enables drone users to download and install applications via the Weibo software development kit (SDK). “During this process, the Weibo SDK also collects the user’s private information and transmits it to Weibo,” the report states.

The volume of user data available to DJI and Weibo could leave the drone user vulnerable to hacking by a malicious actor, who “may attempt to compromise DJI’s and Weibo’s servers to exploit this functionality themselves,” the report states.

In addition, the GRIMM report also notes that The DJI GO 4 application restarts itself, after the drone user tries to swipe it closed, allowing it to continue to run in the background even though the the user might believe the app is closed.

“The DJI GO 4 application contains several suspicious features as well as a number of anti-analysis techniques, not found in other applications using the same SDKs,” the report notes.

In its statement DJI said, “The hypothetical vulnerabilities outlined in these reports are best characterized as potential bugs.”

The drone developer said it has safeguards in place to prevent the download of an unofficial, or “hacked,” version of one of its apps. When it detects hacked versions of a DJI app – for example if the app has been modified to remove flight safety features, such as altitude restrictions – the company will notify the user and require the download of the more recent official version of the app from the DJI website.

If the user does not consent, DJI said it would disable the hacked version of the app.

In any case, since the DJI GO4 app is primarily used as the flight operation of its recreational drones, the potential vulnerabilities described in the two reports do not extend to drones used by government agencies, the company said. “DJI’s drone products designed for government agencies do not transmit data to DJI and are compatible only with a non-commercially available version of the DJI Pilot app.”

For its recreational drones that do use the DJI GO4 app, DJI said it integrates its consumer apps with the leading social media sites via those sites’ SDKs. It referred questions about the security of the SDKs to their respective social media services. “However, please note that the SDK is only used when our users proactively turn it on,” DJI said.

The company also disputed the cybersecurity firms’ finding that DJI GO 4 was able to restart itself after being closed by the user. “We are investigating why these researchers claim it did so. We have not been able to replicate this behavior in our tests so far,” DJI said.

“We design our systems so DJI customers have full control over how or whether to share their photos, videos and flight logs, and we support the creation of industry standards for drone data security that will provide protection and confidence for all drone users.”

Over the past several years, DJI and other China-based drone companies have faced numerous questions over the security of the data collected from users. Several bills have been filed in Congress to limit the use by federal agencies of drones manufactured in, or containing components produced in, China. Earlier this year, the U.S. Department of the Interior (DOI) grounded all non-emergency operations for its entire fleet of 800 drones, citing potential security risks.

DJI, whose drones comprised a small portion of the DOI fleet, blasted the move, “which inappropriately treats a technology’s country of origin as a litmus test for its performance, security and reliability.”

In an interview, DJI spokesman Michael Oldenburg said rather than instituting a so-called country-of-origin system of drone regulation, the U.S. should establish a national set of rules regulating the cybersecurity of all unmanned aerial systems. “We’re advocating that in order to make things more secure — and it’s not just for DJI drones, but drones from any manufacturers — there should be clear and transparent guidelines and standards that those manufacturers make sure their products meet,” he said.

Miriam McNabb

Miriam McNabb is the Editor-in-Chief of DRONELIFE and CEO of JobForDrones, a professional drone services marketplace, and a fascinated observer of the emerging drone industry and the regulatory environment for drones. Miriam has penned over 3,000 articles focused on the commercial drone space and is an international speaker and recognized figure in the industry.  Miriam has a degree from the University of Chicago and over 20 years of experience in high tech sales and marketing for new technologies.
For drone industry consulting or writing, Email Miriam.

TWITTER:@spaldingbarker

Subscribe to DroneLife here.

Filed Under: Drone News Feeds, Featured, News Tagged With: chinese drone tech, DJI, DJI GO App, DJI Security

Reader Interactions

Trackbacks

  1. DJI Says Promises About Application Stability Misleading | Cool Gadgets says:
    August 7, 2020 at 5:10 am

    […] protection are normally properly publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: following which they rapidly released a next assessment of the […]

    Reply
  2. DJI Says Claims About App Security Misleading | Aerial Division says:
    August 7, 2020 at 3:13 am

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  3. DJI Says Claims About App Security Misleading – My Blog says:
    August 6, 2020 at 9:49 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  4. DJI Says Claims About App Security Misleading - Lingeriestore says:
    August 6, 2020 at 7:06 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  5. DJI Pilot App Security: DJI Says Claims About App Security Misleading – Drones Crunch says:
    August 6, 2020 at 5:12 pm

    […] app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  6. DJI Says Claims About App Security Misleading | Gadgets says:
    August 6, 2020 at 2:54 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  7. DJI Responds to Reports of Potential Go App Security Problems - Go Drones Blog says:
    July 30, 2020 at 10:51 pm

    […] Reports of potential DJI Go App security problems identified by research firms are “potential bugs,” says the manufacturer. Source […]

    Reply
  8. DJI Responds to Reports of Potential Go App Security Problems ⋆ says:
    July 30, 2020 at 4:34 am

    […] The complete article is here […]

    Reply
  9. DJI Responds to Reports of Potential Go App Security Problems | Anti Corruption Digest says:
    July 29, 2020 at 8:28 pm

    […] Source: DJI Responds to Reports of Potential Go App Security Problems […]

    Reply
  10. DJI Responds to Reports of Potential Go App Security Problems – DroneLife - On Sale Drones says:
    July 29, 2020 at 5:50 pm

    […] DJI Responds to Reports of Potential Go App Security Problems  DroneLife […]

    Reply
  11. DJI Go App Security Problems: DJI Responds to Reports of Potential Flight System Software Vulnerabilities | Drone Magazine says:
    July 29, 2020 at 1:59 pm

    […] Source […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

AeroDefense Launches No-Cost Drone Detection Access Program for Law Enforcement

AirWarden Essentials customers can now share drone detection data with SLTT, DHS, and FBI partners at no added cost AeroDefense…

Continue Reading AeroDefense Launches No-Cost Drone Detection Access Program for Law Enforcement

Versaterm Acquires Aloft to Expand Drone Capabilities for Public Safety

Deal adds FAA-approved airspace intelligence to DroneSense platform Versaterm has announced the acquisition of Aloft, an FAA-approved provider of airspace…

Continue Reading Versaterm Acquires Aloft to Expand Drone Capabilities for Public Safety

Trojan Horse or Trade Dispute? Texas Attorney General Targets Anzu in High-Stakes Drone Lawsuit

Texas AG sues Anzu, claims company sells DJI clones By DRONELIFE Features Editor Jim Magill Claiming that the company is…

Continue Reading Trojan Horse or Trade Dispute? Texas Attorney General Targets Anzu in High-Stakes Drone Lawsuit

Geo Week to Relocate to Salt Lake City in 2027

Leading Geospatial Event Moves to Utah’s Expanding Technology Hub Geo Week will relocate to Salt Lake City, Utah in 2027,…

Continue Reading Geo Week to Relocate to Salt Lake City in 2027

Eric Trump Invests in XTEND as Israeli Drone Firm Announces Plan to Go Public via Nasdaq Merger

AI-powered robotics company targets $1.5B valuation in U.S. listing Israeli drone and robotics company XTEND has announced plans to go…

Continue Reading Eric Trump Invests in XTEND as Israeli Drone Firm Announces Plan to Go Public via Nasdaq Merger

New Partnership Building Farming Drone Batteries in Texas

KULR Technology Group and Hylio have entered a joint collaboration to produce NDAA-compliant battery systems for agricultural drones built in…

Continue Reading New Partnership Building Farming Drone Batteries in Texas

FlytBase Unveils FlytBase One Management System

FlytBase has introduced FlytBase One, a unified control platform built to connect autonomous drones, robots, and physical infrastructure. The company also…

Continue Reading FlytBase Unveils FlytBase One Management System

Sentrycs Scout Expands Counter-Drone Capabilities for Law Enforcement

Sentrycs, an Ondas Inc. subsidiary specializing in counter-drone technology, has delivered its C-UAS solution to a German State Police department.…

Continue Reading Sentrycs Scout Expands Counter-Drone Capabilities for Law Enforcement

Training for the Threat: FBI Expands Counter-Drone Force Ahead of Historic World Cup

FBI on track to train 60 state, local officers in drone mitigation by June By DRONELIFE Features Editor Jim Magill…

Continue Reading Training for the Threat: FBI Expands Counter-Drone Force Ahead of Historic World Cup

Spexi Orthomosaic Drone Imagery Now Available on SkyWatch Platform

SkyWatch has announced the addition of Spexi orthomosaic drone imagery to its platform, expanding access to standardized aerial data for…

Continue Reading Spexi Orthomosaic Drone Imagery Now Available on SkyWatch Platform

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT